{"id":"CVE-2019-25777","details":"YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution.\n\nA perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options.\n\nA perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code.","modified":"2026-10-08T02:45:14.356435327Z","published":"2026-10-05T07:16:29.557Z","database_specific":{},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/10/05/7"},{"type":"WEB","url":"https://metacpan.org/release/TINITA/YAML-1.28/changes"},{"type":"REPORT","url":"https://github.com/ingydotnet/yaml-pm/issues/212"},{"type":"FIX","url":"https://github.com/ingydotnet/yaml-pm/commit/bace96b5e6661d521c7c515c94a09e081c911fce.patch"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ingydotnet/yaml-pm","events":[{"introduced":"0"},{"fixed":"b3c7869c21e7f71364394b817b55cae46fd74fa8"},{"fixed":"bace96b5e6661d521c7c515c94a09e081c911fce"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.27_001"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["1.27","1.26_001","1.26","1.25_002","1.25_001","1.25","1.24_002","1.24_001","1.24","1.23_003","old-yaml-pm-1.23","1.23","1.22","1.21","1.20_002","1.20_001","1.20","1.19_001","1.19","1.18_001","1.18","1.17","1.16_002","1.16_001","1.16","1.15","1.14","1.13","1.12","1.11","1.10","1.09","1.08","1.07","1.06","1.05","1.04","1.03","1.02","1.01","1.00","0.99","0.98","0.97","0.96","0.95","0.94","0.93","v0.92","v0.91","v0.90","v0.89","0.88","0.87","0.86","0.85","0.84","0.83","0.82","0.81","0.80","0.79","0.78","0.74","0.77","0.76","0.75","0.73","0.72","0.71","0.70","0.68","0.67","0.66","0.65","0.64","0.63","0.62","0.61","0.60","0.58","0.57","0.56","0.55","0.54","0.53","0.52","0.51","0.50","0.49_70","0.39","0.38","0.37","0.36","0.49_01","0.35","0.30","0.26","0.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25777.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}